Revolut hit by phishing attack using fake government emails

Revolut says a phishing campaign using fake government emails stole staff credentials and allowed access to internal systems and customer data; the company is investigating.

Revolut, the UK-headquartered fintech, confirmed a data breach after a phishing campaign used fake government emails to trick staff into revealing login credentials. Attackers then used those credentials to access internal systems and obtain customer information.

Employees received emails that appeared to come from government bodies and were prompted to click links or open attachments that captured login details. The company describes the incident as a social-engineering campaign that impersonated official communications to harvest credentials.

The firm opened an investigation and engaged external cybersecurity specialists to contain the incident and assess the scope of exposed information. Revolut is cooperating with relevant regulators and law enforcement.

In a statement, Revolut said, “We have opened an investigation and engaged external cybersecurity specialists to contain the incident and assess the scope of exposed information.”

Revolut has forced password resets and applied additional verification to impacted accounts. IT teams closed compromised accounts, revoked tokens linked to the incident and increased monitoring of network activity. The company said multi-factor authentication and monitoring tools limited the attackers’ movements after initial access.

Revolut serves millions of retail and business customers across Europe and other regions. Where personal data was affected, users have been notified directly and given guidance on changing passwords and enabling stronger authentication.

The company is reviewing email filtering and staff training programs to reduce the risk of similar breaches. Customers were advised to check accounts for unusual transactions and to report any suspicious activity immediately.

Cybersecurity specialists say campaigns that impersonate government agencies often use official logos, formal language and plausible pretexts such as tax or regulatory notices to lower suspicion and prompt quick action.

The investigation remains ongoing. The company said it will update customers and regulators as more information becomes available and urged users to verify unexpected requests that appear to come from government bodies by contacting the issuing agency through official channels.

Articles by this author